@@ -11,8 +11,7 @@ To get your Relay set up, you will need to give Smallstep the following informat
1111
1212- ** Relay Trust Bundle** . This will be used by the Relay to verify client certificates.
1313This bundle needs to include both Root and Intermediate CA certificates for any CAs you want your Relay to trust.
14- These can include Smallstep or custom CAs.
15- A typical configuration will include the Smallstep Account Root and Intermediate CA.
14+ A typical configuration will include your team's Smallstep Accounts Root and Intermediate CA.
1615- ** Relay Region** . The GCP region for the relay, eg. ` US_CENTRAL1 `
1716
1817## Client Configuration
@@ -30,17 +29,17 @@ The Relay’s server certificate is issued by your team’s Workloads Intermedia
3029So, your clients will need to trust the Workloads Root CA.
3130You can download the Workloads Root CA certificate from your [ Authorities] ( https://smallstep.com/app/?next=/cm/authorities ) page.
3231
33- ## Example: Create a Jamf Configuration Profile
32+ ## Example: Jamf Pro Configuration Profile
3433
3534In this example, we’ll use Jamf Pro to configure endpoints connecting to a Smallstep Relay.
3635
3736** In the Smallstep console:**
3837
39- 1 . Visit [ Authorities] ( https://smallstep.com/app/?next=/cm/authorities ) .
38+ 1 . Visit [ Authorities] ( https://smallstep.com/app/?next=/cm/authorities )
4039 1 . Select the ** Smallstep Accounts** authority
4140 2 . Download the Root Certificate
4241 3 . Under the Provisioners section of the page, choose the provisioner named ` acme-da `
43- 4 . Temporarily save the ** URL shown on the page, eg.** ` https://accounts.example.ca.smallstep.com/acme/acme-da/directory `
42+ 4 . Temporarily save the ** URL shown on the page** , eg. ` https://accounts.example.ca.smallstep.com/acme/acme-da/directory `
44432 . Return to [ Authorities] ( https://smallstep.com/app/?next=/cm/authorities )
4544 1 . Select the ** Smallstep Workloads** authority
4645 2 . Download the Root Certificate
@@ -52,12 +51,12 @@ In this example, we’ll use Jamf Pro to configure endpoints connecting to a Sma
52513 . Add a new Configuration Profile
5352 1 . Choose ** Options → General**
5453 - Name: Smallstep
55- 2 . For ACME CA trust, add a [ ** Certificate payload** ] ( https://support.apple.com/guide/deployment/certificates-payload-settings-dep91d2eb26/web )
54+ 2 . For ACME CA trust, add a ** [ Certificate payload] ( https://support.apple.com/guide/deployment/certificates-payload-settings-dep91d2eb26/web ) **
5655 - Certificate Name: ** Smallstep Accounts Authority**
5756 - Certificate Option: ** Upload**
5857 - Certificate Upload: (upload the Accounts Root CA certificate)
5958 - Allow all apps access: ☑️
60- 3 . For Relay server trust, add a [ ** Certificate payload] ( https://support.apple.com/guide/deployment/certificates-payload-settings-dep91d2eb26/web ) **
59+ 3 . For Relay server trust, add a ** [ Certificate payload] ( https://support.apple.com/guide/deployment/certificates-payload-settings-dep91d2eb26/web ) **
6160 - Certificate Name: ** Smallstep Workloads Authority**
6261 - Certificate Option: ** Upload**
6362 - Certificate Upload: (upload the Workloads Root CA certificate)
0 commit comments